SOC Analyst, Tier 1 Nadia Belhaj
SOC Analyst, Tier 1
[email protected] | (703) 555-1552 | Arlington, United States
Profile
SOC analyst working Tier 1 on a 24x7 managed security team covering nine client tenants, with CompTIA Security+ and Network+. Triage roughly 120 alerts a shift in Splunk Enterprise Security and CrowdStrike Falcon, with a median time to acknowledge of 4 minutes against a 15 minute service target and an escalation rate of 14%. Wrote 11 of the triage playbook entries the current shift uses and completed the internal Tier 2 readiness program.
Work Experience
01/2026 - Present, SOC Analyst, Tier 1, Braxwell Managed Security, Arlington, United States
- Triage roughly 120 alerts a shift across 9 client tenants on a 24x7 follow-the-sun roster, escalating 14% to Tier 2.
- Median time to acknowledge of 4 minutes against a 15 minute contractual service target, measured across my shifts over two quarters.
- Work the queue in Splunk Enterprise Security with CrowdStrike Falcon endpoint telemetry and a SOAR platform for phishing triage.
- Wrote 11 entries in the shift triage playbook, including the current phishing and impossible-travel procedures.
- Proposed the tuning that cut a noisy scheduled-task rule from 90 alerts a week to 12 with no missed true positives in a 30 day review.
09/2023 - 12/2025, IT Service Desk Technician, George Mason University, Fairfax, United States
- Handled around 25 tickets a day covering account lockouts, multifactor enrollment, phishing reports and endpoint reimaging.
- Escalated 140 reported phishing messages to the university security team and built the triage checklist the desk still uses.
Education
08/2022 - 12/2025, Bachelor of Science, Information Technology, cybersecurity concentration, George Mason University, Fairfax, United States
Coursework in network defense, digital forensics and security operations. Built a home lab running Elastic Security with Sysmon and Zeek log sources and 18 self-written detections.
Skills
Alert triage and escalation, 75
Splunk Enterprise Security and SPL, 65
CrowdStrike Falcon, 65
Phishing analysis and email header review, 75
MITRE ATT&CK mapping, 60
Windows and Active Directory log analysis, 65
Python and PowerShell scripting, 55
Playbook and runbook writing, 70
Languages
English, native
Arabic, native
French, intermediate
Certificates
08/2025, CompTIA Security+, CompTIA
Exam SY0-701.
11/2024, CompTIA Network+, CompTIA
Summary
A SOC analyst resume is a one to two page document that states which tier you worked, how much alert volume you handled, which SIEM and EDR you used by name, and what the detections you wrote actually changed. This guide gives you three adaptable versions, the operational block most applicants leave out, and current Bureau of Labor Statistics pay and outlook for the occupation.
SOC Analyst resume examples by experience level
In short, a SOC analyst resume is a one to two page document that names your tier, your queue, your tooling and the detections you authored.
Security operations, in fact, is one of the few jobs in technology with a native metric surface. In other words, you work inside a system that counts things: alerts per shift, escalation rate, time to acknowledge, time to contain, rules tuned. A SOC manager knows those numbers exist; therefore, a resume that omits all of them is not modest. It is unreadable. The reader cannot tell whether you triaged 20 alerts a shift or 200, or whether you closed tickets or wrote the logic that created them.
Resume guide for a SOC analyst resume
Specifically, this guide and the corresponding SOC analyst resume example will cover:
- How to write a SOC analyst resume, section by section
- The operational block: tier, queue, stack, timing and detections
- Three adaptable summaries: Tier 1, Tier 2 and detection engineering
- Which certifications actually gate SOC hiring
- What the job market looks like and what you can expect to earn
How to write a SOC analyst resume
Overall, six sections: contact header, summary, certifications, an operational block, security operations experience, and education. Generally, one page in your first three years, two once you are writing detections and running incidents.
Certifications sit high because here they are a filter rather than a decoration, and in federal and defense contracting a contractual condition. The operational block sits under them because it answers the question the rest of the page cannot.
| Section | What it is answering | Where it goes |
|---|---|---|
| Certifications | Does this person clear the contract or the posting's stated bar? | Directly under the summary, with dates |
| Operations block | Which tier, which queue, which tools, which detections? | Its own block, before experience |
| Experience | What did they investigate, decide and change? | Reverse chronological, with numbers |
| Education | Does it clear the stated degree requirement? | Bottom, unless you graduated this year |
Say which ATT&CK version you mapped your detections against
If you write that your detections cover MITRE ATT&CK techniques, say which release you mapped against, because the taxonomy moved this year.
ATT&CK v19 was published on 28 April 2026 with 222 techniques and 475 sub-techniques in Enterprise, and it split the Defense Evasion tactic into two new tactics, Stealth and Defense Impairment. A further release, v19.2, followed on 6 August 2026 (MITRE ATT&CK release notes, 2026).
So "42 detections mapped to 31 ATT&CK techniques, v19 Enterprise" is a claim a reader can check, and "ATT&CK aligned" is not. Name three or four technique IDs you have genuinely written for, and be ready to describe the logic of each.
Run the finished file through the ATS resume checker before you submit, because large employers and federal contractors parse applications into a structured record first.
Choosing the best resume format for a SOC analyst resume
Reverse chronological, then, with the operational block breaking the pattern between the certifications and the first job. One page for your first three years, two after that.
However, functional formats fail here for the reason they fail everywhere the work is tiered: a manager is reading to place you on a shift roster, and tier progression over time is what they place you by. Thus, a format that hides the sequence hides the variable that matters.
Include your contact information
| ✅ Right | ❌ Wrong |
|---|---|
| Nadia Belhaj | Nadia Belhaj |
| SOC Analyst, Tier 2, Incident Response and Detection Engineering | Cyber security professional seeking new opportunities |
| Security+, GCIH, CISSP. Active clearance, eligible for a polygraph | Various security certifications |
| (703) 555-1552, [email protected], Arlington, VA | (703) 555-1552, [email protected] |
Above all, put your tier in the title line. "SOC Analyst" alone does not say whether you triage a queue, run investigations or build detections, and those are three different hires filling three different gaps on a roster.
If you hold a clearance, say the level and its status; if you do not, leave clearances off the page entirely. At the same time, never put a case identifier, a client name or an indicator of compromise on a resume.
Make use of a summary
In short, four lines: tier and function, years, your stack by name, and one operational number.
SOC analyst working Tier 1 on a 24x7 managed security team covering nine client tenants, with CompTIA Security+ and Network+. Triage roughly 120 alerts a shift in Splunk Enterprise Security and CrowdStrike Falcon, with a median time to acknowledge of 4 minutes against a 15 minute service target and an escalation rate of 14%. Wrote 11 of the triage playbook entries the current shift uses and completed the internal Tier 2 readiness program.
SOC analyst with seven years in security operations, currently working Tier 2 investigations and detection tuning for a federal services provider. Handle around 40 escalated investigations a week across Microsoft Sentinel and Defender for Endpoint, with a median time to detect of 11 minutes on the alert classes I own. Authored 46 detections in KQL and Sigma mapped to 31 ATT&CK techniques, and retired a rule family that had been generating 310 alerts a week without a single confirmed true positive.
Senior SOC analyst with eleven years in security operations, leading detection engineering for a 14-person team running a 24x7 queue. Own a library of 210 production detections and cut the monthly alert volume by 38% across two tuning cycles while confirmed true positives rose. Ran incident command on 9 confirmed intrusions in the last two years against a process aligned to NIST SP 800-61 Revision 3, and hold CISSP, GCIA and GCIH.
Right vs wrong: the same SOC analyst summary, twice
| ✅ Right | ❌ Wrong |
|---|---|
| SOC analyst with seven years in security operations, currently working Tier 2 investigations and detection tuning. | Cyber security professional with experience in security operations and threat detection. |
| Handle around 40 escalated investigations a week across Microsoft Sentinel and Defender for Endpoint. | Experienced with various SIEM and endpoint security tools. |
| Authored 46 detections in KQL and Sigma mapped to 31 ATT&CK techniques. | Familiar with the MITRE ATT&CK framework and industry best practices. |
For instance, the left column can be placed on a roster tomorrow. The right column, on the other hand, could be a Tier 1 analyst eight months in or a manager who has not opened a console in five years, and a reader with a gap on a night shift cannot afford to find out in the interview.
Outline your security operations experience
Then list employer, tier, dates, and one line saying what the SOC was: internal, managed service or hybrid, its size and its coverage model. Then three to five bullets, each naming a decision and a number.
| Instead of | Use |
|---|---|
| Monitored security alerts and escalated as needed | Triaged roughly 120 alerts a shift across 9 client tenants, escalating 14% with a median 4 minute acknowledgment |
| Created detection rules | Authored 46 detections in KQL and Sigma covering 31 ATT&CK techniques, including three for credential dumping behavior |
| Reduced false positives | Retired one rule family generating 310 alerts a week with no confirmed true positives in the preceding 90 days, after a documented backtest |
SOC Analyst, Tier 2, Kestrel Federal Services, Arlington, VA, April 2022 to Present
Internal SOC of 14 analysts, 24x7 follow-the-sun roster, roughly 9,000 endpoints and 40 cloud subscriptions.
Run around 40 escalated investigations a week in Microsoft Sentinel with Defender for Endpoint telemetry, median time to detect 11 minutes on the alert classes I own.
Authored 46 production detections in KQL and Sigma mapped to 31 ATT&CK techniques, v19 Enterprise, including the identity anomaly set now used across all business units.
Retired a legacy rule family producing 310 alerts a week with no confirmed true positives in 90 days, after a documented backtest and a 30 day shadow period.
Led containment on a confirmed business email compromise: isolated 4 endpoints, revoked 6 active sessions and contained it 38 minutes after escalation, following the team's process against NIST SP 800-61 Revision 3.
Your tier, your queue and the detections you wrote
This is the block almost nobody includes, even though it is the one that gets you onto a roster. Six lines, each answering a question a SOC manager asks in the first minute.
Your tier and the model you worked in. Tier 1, Tier 2, Tier 3, or a flat pod model with no tiers. Whether the SOC was internal, a managed security service provider, or a hybrid with an outsourced night shift. Whether coverage was 24×7, follow-the-sun, or business hours with on-call. Those three facts place you before anything else on the page.
Your queue. Alerts per shift or per week that you personally handled, your escalation rate if you were Tier 1, your investigation count if you were Tier 2. These separate a busy SOC from a quiet one, and a quiet one is not a mark against you as long as the reader can see which you came from.
Your stack, by name and by your role in it. Not "SIEM experience". Name the SIEM (Splunk Enterprise Security, Microsoft Sentinel, Elastic Security, QRadar), the EDR (CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne), and anything else you genuinely used. Then say what you did with each: wrote searches, tuned rules, built playbooks, or used what someone else built. Those are different skills and readers price them differently.
Your timing, if you can state it honestly. Time to detect, acknowledge and contain. Give the definition and the window with the number, because no two SOCs measure these the same way. "Median time to acknowledge of 4 minutes against a 15 minute service target, measured across my shifts over two quarters" is defensible; a bare "MTTD: 11 minutes" invites a question you may not want. If your SOC does not measure it, leave it out rather than estimating.
The detections you wrote, and what they cut. This separates an analyst who works a queue from one who changes it. Give the count, the language (SPL, KQL, Sigma, Suricata, YARA), the ATT&CK version you mapped against, and above all what the work did to volume: what you tuned and what you retired. Tuning that cuts alert volume without losing true positives is the most valuable thing a mid-level analyst does, and it is almost never on the resume.
Incident process and redaction on a SOC resume
The process you followed. Name the incident handling process and what it is aligned to. NIST published SP 800-61 Revision 3, "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile", in April 2025, restructuring incident response guidance around the Cybersecurity Framework 2.0 functions. If your team has moved to that structure, say so; if not, name what you actually follow. Either answer beats silence.
Tier and model: Tier 2 investigations and detection engineering, internal SOC of 14, 24x7 follow-the-sun roster, roughly 9,000 endpoints and 40 cloud subscriptions.
Queue: about 40 escalated investigations a week; 11 minute median time to detect on owned alert classes, measured over four quarters.
SIEM and EDR: Microsoft Sentinel (author searches, analytics rules and workbooks), Microsoft Defender for Endpoint (investigate, isolate, live response), Tenable, Proofpoint, and a SOAR platform for containment playbooks.
Detection content: 46 production detections in KQL and Sigma mapped to 31 ATT&CK techniques, v19 Enterprise; retired one rule family generating 310 alerts a week with no confirmed true positives in 90 days.
Process: incident handling aligned to NIST SP 800-61 Revision 3 (April 2025); containment authority for endpoint isolation and session revocation without escalation.
Redact properly. Above all, no client names, case numbers, hostnames, indicators of compromise or ticket identifiers, and nothing about work on a classified system beyond what its guidance permits. Instead, describe the shape of the work and the size of the environment: "nine client tenants, roughly 9,000 endpoints" tells a reader everything and identifies nobody.
The entry point moved this year, and your detection content should show it
The Verizon 2026 Data Breach Investigations Report, published on 19 May 2026, found that exploitation of software vulnerabilities was the leading breach entry point at 31%, overtaking stolen credentials for the first time in the report's nineteen years. It also found third parties involved in 48% of breaches (Verizon DBIR, May 2026).
Meanwhile the Bureau of Labor Statistics projects information security analyst employment to grow 21% from 2025 to 2035, adding 40,600 jobs, against about 14,100 openings a year (BLS, 2025-35 projections).
Together those say what belongs on the page: detection content covering exploitation and third-party access reads as current, and a page built entirely around phishing reads as three years old.
Build a snapshot of your key skills
Twelve to eighteen entries in four labeled groups, so a manager can scan for their own stack in one pass.
Detection and monitoring: Microsoft Sentinel, Splunk Enterprise Security, Elastic Security, KQL, SPL, Sigma rule authoring, backtesting and tuning
Endpoint and network: Microsoft Defender for Endpoint, CrowdStrike Falcon, Suricata, Zeek, Wireshark, host triage and memory capture
Response and process: incident handling to NIST SP 800-61 Revision 3, containment and eradication, phishing analysis, malware triage, SOAR playbooks, postmortems
Context and scripting: MITRE ATT&CK mapping, threat intelligence enrichment, Python, PowerShell, SQL for log analysis, Active Directory and Entra ID investigation
List your education and certifications
Certifications first, with the issuing authority and the year, then the degree. Moreover, four credentials do most of the gating in SOC hiring:
| Credential | What it is | Authority |
|---|---|---|
| CompTIA Security+ | Current exam code SY0-701, maximum 90 questions, passing score 750 on a 100 to 900 scale; the English version retires on 11 June 2027 | CompTIA, September 2026 |
| GIAC GCIH | Incident handling: 106 questions, 4 hours, passing score 69% for exams released on or after 10 May 2025 | GIAC, September 2026 |
| GIAC GCIA | Intrusion analysis: network and host monitoring, traffic analysis and intrusion detection; 106 questions, 4 hours, 67% to pass | GIAC, September 2026 |
| ISC2 CISSP | Five years of required work experience is published as the bar, which puts it out of reach for most Tier 1 analysts | ISC2, September 2026 |
For defense or federal contract work, one more document also decides your file. Specifically, DoD Manual 8140.03, "Cyberspace Workforce Qualification and Management Program", was issued on 15 February 2023 and canceled the older DoD 8570.01-M from 2005. In addition, it requires foundational qualification through education, training, or a certification accredited to ISO/IEC 17024, plus on-the-job qualification for the work role within 12 months (DoD CIO, DoDM 8140.03). If a posting names a work role and a qualification level, put the matching credential where a reader sees it in four seconds.
Certifications: ISC2 CISSP (2023). GIAC Certified Intrusion Analyst, GCIA (2021). GIAC Certified Incident Handler, GCIH (2019). CompTIA Security+ (2015, renewed 2024).
Bachelor of Science, Information Technology, cybersecurity concentration, George Mason University, Fairfax, VA, 2015
Clearance: active, current; eligible for additional adjudication.
Choose the right layout and design
For layout, then, single column, 10 or 11 point body type, clear headings, no photograph, no graphics, no skill bars. PDF unless the portal says otherwise.
Government and contractor portals parse applications into a structured record before anyone opens them, and two-column templates are where that parsing fails. After all, a file whose certifications block arrives interleaved with its education has lost the screen that was checking for Security+.
Put your tier in the title line and your certifications with dates under the summary. Give alert or investigation volume with the period it covers. Name the SIEM and the EDR and say what you did with each. State the ATT&CK version you mapped against. Say what your tuning did to volume and to true positives.
Do not write "SIEM experience" or "familiar with MITRE ATT&CK"; both are invisible next to a named tool and a technique count. Do not put a case number, client name, hostname or indicator on the page. Do not list a certification you are studying for as though you hold it. Do not claim containment authority you did not have. Do not estimate a metric your SOC does not measure.
SOC analyst job market and outlook
A small occupation growing very fast, an unusual and favorable combination for a candidate.
| Measure | Value |
|---|---|
| Information security analyst jobs, 2025 | 192,900 |
| Projected change, 2025-35 | 21% (much faster than average), +40,600 |
| Projected annual openings | ~14,100 |
| Typical entry-level education | Bachelor's degree |
| Work experience in a related occupation | Less than 5 years |
| Median annual wage, May 2025 | $129,180 |
Source: U.S. Bureau of Labor Statistics, Occupational Outlook Handbook, 2025-35 projections and May 2025 wage data.
Note the experience line. BLS records this occupation as typically requiring experience in a related occupation, commonly network or systems administration, which is why a help desk or systems role is an asset rather than something to bury. In that case, write it as security-adjacent work: what you hardened, monitored and escalated.
Where the work sits, by median pay:
| Industry | Median annual wage (May 2025) |
|---|---|
| Information | $138,650 |
| Computer systems design and related services | $132,410 |
| Finance and insurance | $130,630 |
| Management of companies and enterprises | $128,950 |
| Consulting services | $125,420 |
Source: U.S. Bureau of Labor Statistics, May 2025.
What salary you can expect as a SOC analyst
To begin with, the median annual wage for information security analysts was $129,180 as of May 2025. The lowest 10 percent earned less than $75,090 and the highest 10 percent more than $199,850 (BLS, May 2025).
SOC roles sit across that whole range; however, three things the resume can speak to decide where. Tier is the first: a Tier 1 triage seat and a Tier 3 detection engineering seat are the same occupation in the data and very different jobs in the pay band, which is the argument for putting your tier in the title line rather than leaving it to be inferred.
Shift is the second. Night, weekend and holiday coverage usually carries a differential, and a candidate who has worked a rotating roster and says so is answering a staffing problem the manager already has.
Certification and clearance are the third, and in federal contracting the credential is a contractual condition rather than a preference. The industry spread above is narrow for a technology occupation, $13,230 between the highest and lowest published industry medians, so tier progression and credentials move your pay far more than employer choice does.
Key takeaways for a SOC analyst resume
- State your tier and coverage model in the title line; they place you before anything else.
- First of all, give the queue a number: alerts a shift, investigations a week, escalation rate.
- Name the SIEM and the EDR, and say whether you used them or wrote in them.
- Also give timing metrics only with their definition and window, or leave them out.
- Likewise, lead the detection line with what the tuning did to volume and to true positives.
- In addition, name the incident process and what it is aligned to.
- Finally, put certifications with dates high, and redact anything identifying a case, client or host.
Build your SOC analyst resume in 15 minutes with our AI resume builder.
Related information technology resume examples
- Cyber security resume
- Network engineer resume
- Network administrator resume
- Network systems analyst resume
- System administrator resume
- IT specialist resume
- IT help desk resume
- Systems analyst resume
- Data analyst resume
- IT manager resume
- DevOps engineer resume
- IT director resume
Pair it with a matching SOC analyst cover letter.
SOC analyst resume questions, answered
How long should a SOC analyst resume be?
One page for your first three years, two once you are writing detections, running incidents or leading a shift. The operations block earns its space at either length, because it replaces a paragraph of adjectives with five lines a manager can act on.
What certifications do I need to get a SOC analyst job?
CompTIA Security+ is the common entry bar; its current exam is SY0-701 and the English version retires on 11 June 2027 (CompTIA, September 2026). GIAC GCIH and GCIA are the usual next step for Tier 2 and intrusion analysis work. CISSP publishes a five year work experience requirement (ISC2, September 2026), which puts it beyond most early-career analysts. For defense contract work, check the posting against DoD Manual 8140.03.
How do I write a SOC analyst resume with no SOC experience?
Write the adjacent work as security work. A help desk role where you handled account lockouts, phishing reports and endpoint reimaging is relevant, and BLS records related work experience as typical for this occupation. Then add a home lab described like a job: the SIEM you deployed, the log sources you ingested, and the detections you wrote. Name the tools, give counts, and put Security+ at the top.
Should I put my alert volume and metrics on a resume?
Yes, with their definition and window. Volume tells a reader what scale you have worked at, which nothing else on the page does. Timing metrics are useful only when you can say how they were measured, since MTTD and MTTR mean different things in different SOCs.
Is a degree required to work in a SOC?
The Bureau of Labor Statistics gives a bachelor's degree in a computer science field as the typical entry-level education for information security analysts, along with related work experience (BLS, 2025-35 projections). In practice many SOCs hire on certification and demonstrable skill, particularly Tier 1 seats at managed service providers. Federal and contractor postings are the least flexible, because the requirement is written into the contract.